Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encryption protects backup data from being read by someone without the key; it does not, by itself, keep attackers from reaching, deleting, or replacing the backup, or prove that a clean copy can be restored. Ransomware resilience depends on separation from routine access, trustworthy restore points, protected credentials, and tested recovery. AI adds risk mainly by helping attackers with tasks such as reconnaissance and phishing—not by breaking backup encryption.

What encryption protects—and what it does not

When backup data is encrypted at rest, someone who obtains the storage may be unable to read its contents without the decryption key. That is an important confidentiality safeguard. But a backup system may still be reachable through a network, an administrator account, or a cloud management console. An attacker with sufficient access can potentially delete the files, encrypt them again, alter retention settings, or interfere with the system that manages them.

Encryption also cannot tell you whether a copy contains healthy data or whether the systems and keys needed to restore it are available. CISA’s U.S. #StopRansomware Guide recommends offline, encrypted backups and regular tests of their availability and integrity. The two controls address different risks: encryption helps protect contents; isolation and testing help preserve recoverability.

How an encrypted backup can still fail

It is connected and reachable

A mounted backup drive, continuously connected server, or cloud account accessible with compromised credentials can be within an attacker’s reach. CISA warns that ransomware variants may search for accessible backups and attempt to delete or encrypt them. Encryption at rest does not prevent actions taken through an account or service that is authorized to manage the backup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Elebase USB to USB C Adapter for iPhone 18 Pro Max,USBC Car Charger Adapter
  • Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
  • Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
  • Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
  • Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
  • 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.

It contains the attack’s damage

An intrusion may go unnoticed before files are encrypted. If a backup runs during that period, it may copy damaged or encrypted files. With version rotation or limited retention, later copies can displace older, clean restore points. NIST’s 2020 recovery publication, SP 1800-11, notes that frequent automated backups can preserve encrypted data if they run after an attack. Keeping versions and identifying when the compromise began are therefore part of choosing what to restore.

The job succeeded, but the restore has not been proved

A successful job notification only establishes that a backup process reported success; it does not demonstrate that the data is complete, intact, or usable. Recovery can fail because a necessary configuration is missing, a key is unavailable, software or hardware dependencies cannot be recreated, or restoration takes too long for the service’s needs. NIST’s 2020 guide for managed service providers addresses planning, maintaining, and testing backups as part of disaster recovery.

Rank #2
Anker USB-C Hub, 5-in-1 USB Hub for Laptops, 4K HDMI Multiport Adapter
  • 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
  • 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
  • Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
  • 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
  • What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.

Cloud storage is treated as isolated when it is not

Cloud storage can separate copies from local systems, but a cloud account is not automatically out of reach. Shared-responsibility boundaries, account permissions, retention settings, logs, and delete protections matter. CISA recommends considering controls such as object lock or other deletion protections, versioning, monitoring, and cloud-to-cloud backup. These controls require careful configuration: immutable storage can create costs and may not fit every regulatory requirement.

A clean restore is reconnected to a compromised environment

Restoring files alone does not remove an attacker or repair a compromised environment. Reconnecting restored machines to suspect systems too soon can reintroduce the compromise. CISA advises containing affected systems, prioritizing critical services, and taking care not to reinfect clean systems during recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Anker USB C Hub, 7in1 Multi-Port USB Adapter, 4K@60Hz USBC to HDMI Splitter
  • Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
  • Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
  • Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
  • Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
  • What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.

Data restoration does not reverse data theft

Some ransomware operations combine file encryption with data theft and threats to publish stolen information. A backup can help restore availability, but it cannot retrieve information already exfiltrated or erase resulting privacy, legal, and reputational consequences. CISA, the FBI, and Australia’s ASD’s ACSC discuss this extortion pattern in their 2023 LockBit advisory.

AI changes some attacker workflows, not the rules of encryption

The UK National Cyber Security Centre says threat actors, including ransomware actors, are already using AI to improve the efficiency and effectiveness of some cyber operations, including reconnaissance, phishing, and coding. A 2023 CISA, FBI, and ASD’s ACSC advisory also warns that AI-generated phishing can make malicious messages harder to distinguish from legitimate ones.

Rank #4
Sale
UGREEN USB to USB C Adapter Combo 4-Pack, 10Gbps USB C Converter Space Gray
  • Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
  • Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
  • Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
  • Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
  • Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft

Those assessments support a practical concern: convincing messages or more efficient reconnaissance may help attackers gain access. They do not establish that every ransomware actor uses AI, that AI breaks properly implemented backup encryption, or that a particular AI capability defeats an isolated, tested backup. The backup controls still need to address access, deletion, clean restore points, and recovery.

Design backups around separation, clean versions, and recovery

  • Keep separated copies. Maintain multiple copies in physically separate, segmented, or otherwise isolated locations; make at least one copy offline or unavailable to routine network access where the workflow allows. CISA’s 2023 LockBit advisory describes the 3-2-1 approach: three copies of data, including production data; two types of media; and one off-site copy. This is a practical strategy, not a guarantee of recovery.
  • Use encryption as one layer. Encrypt sensitive backups, and control decryption keys separately from the backup administrator credentials so that a single compromised account does not automatically provide both storage control and key access.
  • Restrict who can administer or delete backups. Segment backup infrastructure, apply least privilege, require multifactor authentication for privileged access, and monitor logs for unusual access or deletion. Separate administrative control where feasible.
  • Protect retention and keep versions. Consider immutable retention, object lock, or delete protection where appropriate. Review who can change the settings, the retention period, compliance obligations, and potential cost before enabling them. Version history helps preserve choices beyond the newest copy.
  • Cover what is needed to rebuild. Include more than user files where recovery depends on applications, identity systems, endpoints, servers, cloud workloads, or configuration. CISA recommends preserving golden images and offline copies of relevant templates and software.
  • Test restores, not just backup jobs. Regularly verify that copies are available and intact, that keys and dependencies can be accessed, and that recovery can meet service needs. Exercise the recovery plan for prioritized systems.

A disconnected external hard drive can serve as one physically separate copy for a compatible device or workflow. Choose sufficient capacity and a connection type your systems support; disconnect it between backup sessions if that suits your process. Protect its encryption key, retain versions rather than relying on one overwritten copy, and test restoring files from it. A drive that remains attached and writable is not meaningfully offline against an attacker who can access that system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anker USB C Hub, 5-in-1 USBC to HDMI Splitter with 4K Display
  • 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
  • Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
  • Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
  • HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
  • What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Compare backup approaches by the failure they address

Approach Isolation Deletion resistance Restore-point and recovery considerations
Offline removable copy Disconnected between backup sessions; physically separate storage is one option CISA describes. Not reachable over the network while disconnected, but protection depends on how it is stored and who can access it when connected. Requires a compatible device, accessible keys, retained clean versions, and tested restoration.
Segmented or logically isolated backup Separated from ordinary systems by network or administrative controls, but may remain reachable to sufficiently privileged accounts. Depends on access restrictions, credentials, retention controls, and monitoring. Version history and regular restore tests help establish whether a clean copy is available.
Cloud backup with retention or object-lock controls Can be separate from local infrastructure, but cloud identity and management access remain important. Delete protection or object lock may resist ordinary deletion when correctly configured; review permissions and compliance needs. Check versions, logs, key access, restore dependencies, and potential costs. CISA notes that multiple cloud providers may reduce vendor lock-in if one provider’s accounts are affected.

No row is a universal winner. The right mix depends on what must be restored, how long copies need to be retained, applicable compliance requirements, operational capacity, and how quickly critical services must return.

Recover in a controlled order

  1. Contain the incident. Isolate affected systems and investigate the scope before treating any backup or restored machine as clean.
  2. Establish a clean recovery environment. Avoid reconnecting suspect systems in a way that could reinfect restored equipment. Confirm access to recovery materials, keys, required software, and configuration.
  3. Select a known-clean restore point. Use retained versions and incident information to avoid choosing a copy that may have captured encrypted or otherwise compromised files.
  4. Restore by service priority. CISA recommends prioritizing critical services and restoring from offline, encrypted backups. Follow a recovery plan that accounts for dependencies, not just the order in which files were backed up.
  5. Verify before normal reconnection. Check the integrity and operation of restored systems and continue monitoring as services return.

The guidance cited here is principally U.S. federal guidance: CISA’s #StopRansomware Guide (September 2023), NIST recovery publications (2020), and the CISA/FBI/ASD’s ACSC LockBit advisory (2023). The AI threat assessment is from the UK NCSC. These sources describe sound resilience practices, not a guarantee that any particular backup design will survive every incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.